Role and Responsibilities Questions
Q1: What exactly is a Data Protection Officer
supposed to do under DPDP?
The DPO serves as the point of contact between the
organization and the Data Protection Board of India. Your responsibilities
include overseeing the organization's data protection strategy, ensuring
compliance with the DPDP Act and Rules, serving as the contact point for data
principals exercising their rights, liaising with the Data Protection Board,
and conducting or overseeing data protection impact assessments. The role
requires both legal understanding and operational capability - you need to
understand the law and translate it into processes your organization can
execute.
Q2: Do I need to be based in India to serve as DPO?
For Significant
Data Fiduciaries, the DPO must be based in India. This is an explicit
requirement under the DPDP Act. For other data fiduciaries, while there is no
strict residency requirement for the privacy lead, having someone in India who
understands the local regulatory landscape and can engage with the Data
Protection Board is practically essential.
Q3: Can the DPO role be combined
with other positions?
The DPDP Act does not explicitly prohibit dual roles, but
the DPO must have sufficient authority and independence to fulfill the role
effectively. Avoid combining the DPO role with positions that create conflicts
of interest - for example, the DPO should not also head the marketing function
that relies heavily on personal data processing.
Consent and Legal Basis Questions
Q4: What makes consent valid under DPDP?
Consent must be free, specific, informed, unconditional, and unambiguous. It
must be given through a clear affirmative action. Pre-ticked checkboxes,
consent bundled with terms of service, or consent conditional on receiving a
service are not valid. Each purpose of processing requires separate consent,
and data principals must be able to withdraw consent as easily as they gave it.
Q5: Can we process personal data without consent?
Yes, in specific
circumstances called legitimate uses. These include processing necessary for
the performance of a function under law, compliance with court orders or
judgments, responding to medical emergencies, processing for employment
purposes, and processing in the public interest. Each legitimate use has
specific conditions that must be met - it is not a blanket exception.
Q6: How
should we handle consent for data we collected before DPDP came into force?
You
need to provide a notice to data principals about the personal data you already
hold and the purposes for which it was collected. If the original collection
was based on consent, that consent remains valid provided the purpose has not
changed. If you want to use previously collected data for new purposes, you
need fresh consent. The DPDP Rules specify the timeline for sending these retrospective
notices.
Q7: Do we need consent for every cookie on our website?
DPDP focuses
on personal data processing, not specifically on cookies. However, cookies that
collect or process personal data - such as those used for behavioral tracking,
personalization, or analytics that identify individuals - require consent.
Strictly necessary cookies that are essential for website functionality may not
require consent, but this should be assessed case by case.
Data Rights and Breach Questions
Q8: What is the timeline for responding to
data principal rights requests?
The DPDP Rules specify response timelines for
rights requests. You should aim to acknowledge receipt within 48 hours and
complete the request within the prescribed period. Having a documented workflow
with assigned responsibilities and tracking mechanisms is essential for meeting
these timelines consistently.
Q9: What counts as a personal data breach under
DPDP?
A personal data breach is any unauthorized processing, accidental or unlawful
destruction, loss, alteration, disclosure, or access to personal data. This is
broader than just external hacking - it includes accidental data exposure,
misdirected emails containing personal data, lost devices with unencrypted
personal data, and insider access violations.
Q10: How quickly must we report a
breach?
The DPDP Act requires notification to the Data Protection Board and
affected data principals without unreasonable delay. The DPDP Rules provide
more specific timelines. Your incident response plan should include clear
criteria for when a security incident becomes a reportable personal data
breach, and the notification process should be pre-documented so it can be
executed quickly during a real incident.
Q11: Do we need to notify every data
principal affected by a breach?
Yes, when the breach is likely to cause harm to
the data principal. The notification must describe the nature of the breach and
the measures the data principal can take to protect themselves. The Data
Protection Board may also direct specific remedial actions.
Cross-Border and Vendor Questions
Q12: Can we transfer personal data outside
India? 
The DPDP Act permits cross-border transfer of personal data to countries
that are not on the restricted list published by the central government. If
your data processing involves transfers to countries on the restricted list,
those transfers are prohibited unless specifically exempted. For countries not
on the restricted list, transfers are permitted, but you must ensure that the
processing by the overseas entity complies with the Act's requirements through appropriate
contractual arrangements. 
Q13: What data processing agreements do we need with
our vendors? 
Every data processor that processes personal data on your behalf
must be governed by a valid contract or data processing agreement. This
agreement should specify the nature and purpose of processing, the types of
personal data involved, the duration of processing, the obligations of the
processor regarding security measures, the requirement to delete or return data
upon termination, and the audit rights of the data fiduciary. 
Q14: Are cloud
service providers considered data processors under DPDP?
Yes. If your
organization uses cloud services to store or process personal data, the cloud
provider is acting as a data processor. Your agreement with the provider must
address DPDP requirements, including data localization if applicable, security
measures, breach notification, and the provider's obligations regarding data
principal rights requests. 
Q15: How do we manage compliance when we use
multiple sub-processors? 
Maintain a register of all sub-processors in your data
processing chain. Ensure that each sub-processor is bound by contractual
obligations that are at least as protective as your agreement with the primary
processor. Implement regular assessments of sub-processor compliance and
maintain visibility into where your data is being processed across the chain.
 
Q: Is DPO
certification required under DPDP?
A: The DPDP Act does not mandate a specific certification for DPOs.
However, having relevant privacy certifications demonstrates competence and is
increasingly expected by organizations and regulators.
Q: Can we
outsource the DPO function?
A: For non-SDF organizations, engaging an external DPO or privacy
consultant is permissible. Significant Data Fiduciaries may need to evaluate
whether the role can be effectively fulfilled externally given the in-India
residency requirement.
QRC provides DPDP compliance advisory and DPO
support services. Contact us to strengthen your data protection program.